VYPR

Nexus Repository Manager 3

by Sonatype

CVEs (24)

  • CVE-2021-34553MedJun 18, 2021
    risk 0.28cvss 4.3epss 0.04

    Sonatype Nexus Repository Manager 3.x before 3.31.0 allows a remote authenticated attacker to get a list of blob files and read the content of a blob file (via a GET request) without having been granted access.

  • CVE-2026-14645MedJul 14, 2026
    risk 0.00cvss epss 0.01

    Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making an outbound HTTP request, allowing a user holding the Capability Administration permission to cause the server to send requests to internal network locations…

  • CVE-2026-14504HigJul 14, 2026
    risk 0.00cvss epss 0.00

    An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on a Swift, Terraform, or Conda hosted repository to upload arbitrary artifacts, bypassing the intended write-permission check.

  • CVE-2026-11403HigJul 14, 2026
    risk 0.00cvss epss 0.01

    A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to gain unauthorized access to repository operations as a targeted user. A format-specific API key realm (NuGet API Key, Docker Bearer Token, or npm Bearer…

Page 2 of 2